First published: Fri Nov 18 2022(Updated: )
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
<1.38.2601.0 | ||
HP Support Assistant | <9.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38395 is a DLL hijacking vulnerability in HP Fusion and HP Support Assistant that can be exploited to elevate privileges.
The DLL hijacking vulnerability in CVE-2022-38395 allows an attacker to exploit Fusion when it launches HP Performance Tune-up, potentially gaining elevated privileges.
HP Fusion versions up to 1.38.2601.0 and HP Support Assistant versions up to 9.11 are affected by CVE-2022-38395.
The severity of CVE-2022-38395 is high, with a CVSS score of 7.8.
To fix CVE-2022-38395, it is recommended to update HP Fusion to version 1.38.2601.0 or later and HP Support Assistant to version 9.11 or later.